Risky Bulletin: Major vulnerability found in ancient TACACS+ networking protocol
In other news: OpenAI agent hacked Australian Medicare website; OpenAI gives Ukraine access to Daybreak; UK to establish anti-disinformation center.
This newsletter is brought to you by SpecterOps, the experts in Attack Path Management. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
A recently disclosed vulnerability can allow attackers to launch pre-authentication remote code execution attacks against TACACS+, a 33-year-old protocol that handles authentication on networking equipment.
The protocol—Terminal Access Controller Access-Control System Plus (TACACS+)—was released in 1993 by Cisco as an upgrade for the original TACACS protocol from 1984.
It works on port 49 and handles authentication, authorisation, and accounting on networking devices. It checks usernames and passwords against a server, allows access to certain operations, and logs what users do on a system.
Whenever users log into a device, like a switch or a router, the client device checks with a network's TACACS+ server if the user exists and what's their access.
Today, the protocol has been baked into almost all modern networking equipment and is in use at almost all large enterprises, at ISPs, data centers, and cloud providers.
Building on previous research, Australian security firm Elttam says it found a way to exploit TACTACS+ and run malicious code on TACTACS+ servers before any authentication can take place.
The attack can be exploited over the internet or a local network when the attacker has a direct line to the central TACACS+ server. This attack involves only two packets and cracking the protocol's weak encryption offline.

Researchers say they can also exploit the bug via intermediary devices, such as the ones sitting at the edge of a network. This variant is, however, less reliant as it is prone to errors due to the different ways device makers and models support the protocol.

Elttam says that while discovering the bug was hard, it was way more difficult to get it patched.
Cisco abandoned the protocol back in the late 90s, and two major versions currently exist, one maintained by Shrubbery Networks and a fork maintained by Facebook. Both of the projects had not released updates in more than half a decade and it took Elttam almost nine months to have some replies to their emails.
Patches are now available for the Shrubbery Networks version, but a CVE has yet to be assigned. The Facebook fork has long been archived and not maintained anymore.
Elttam warns that at least two Chinese cyber-espionage groups have been seen exploiting TACTACS+ over the past two years in operations targeting telecommunications companies across the world—Salt Typhoon and Fire Ant.
In both cases, the groups targeted TACACS servers for persistence and lateral movement, primarily because of the protocol's central role in modern networks.

Risky Business Podcasts
The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, Adam, and James at the helm!
Breaches, hacks, and security incidents
OpenAI agent breaches Medicare portal: Australian PM Anthony Albanese says an OpenAI agent gained unauthorized access to an Australian Medicare portal earlier this year. The agent was allegedly conducting research into public medical spending, found a way to bypass the portal's defences, and accessed both public and non-public files. OpenAI notified the Australian government of the incident on September 10, three months after it happened. Officials are now investigating what data was accessed. [ABC // ABC live feed]
Three other OpenAI incidents: OpenAI agents attempted to hack into at least three public websites earlier this year in incidents predating both the RubyGems and HuggingFace breaches. According to AI non-profit research lab Transluce, the agents abused the urlquery[.]net to bypass site protects and exploit security vulnerabilities. Targeted websites include the Data USA archive of public US government data, the University of New Mexico digital library, and the Australian Institute of Health and Welfare. [Transluce]
Hacker claims new Canva breach: A new hacking group named The Seven Deadly Sins claims to have hacked and stolen sensitive data from Australian graphic design software company Canva. The hackers allegedly breached Canva's Salesforce account at the end of August. The group is now trying to extort the company. This is Canva's second breach after hackers also stole the personal data of 139 million users in 2019. [DataBreaches.net]
Spokane Public Schools incident: The Spokane Public Schools, one of the largest school districts in the state of Washington, took down its IT network this week after a cybersecurity incident. [The Spokesman-Review]
Four crypto-heists: There's major turbulence in the crypto world, where four projects suffered security breaches and lost some of their funds. Nostra lost $3.5 million due to a rigged oracle pool, Astroport and Drop lost $4.9 million and $4.4 million, respectively, from a malicious proposal, and Duelbits also lost $4.2 million from a hot wallet compromise. [Nostra hack // Astroport and Drop hack // Duelbits hack]
Hackers take over LNG cargo ship: A Liberian-flagged LNG cargo ship was forced to dock in a Spanish port after hackers breached on-bord systems. The hackers allegedly compromised systems for controlling tank pressure, safety valves, and boil-off gas management. The ship loaded LNG in New Orleans and was headed to a port in Italy. The incident is the third case of a cargo ship hack disclosed over the past week. The FBI and the US Coast Guard also boarded two vessels in the Gulf of Mexico to investigate cyberattacks. [New Orleans City Business // Splash 24/7]
Stolen FBI data includes sensitive work assignments: The ShinyHunters hacking group has released a sample from the data they stole from the FBI job portal this month. The sample is a 5,000-line spreadsheet with in-depth details on FBI employees working on China, Russia, drug cartels, cyber, and other operations. The group gave the FBI seven days to correct a security alert on the group's activity. The deadline expires in three days. [Reuters]
The data, part of a sample of 5,000 lines released by the hackers, shows which employees are working on “data intercept” or “telecom intercept” technologies, or are in the FBI’s “clandestine technical operations” unit, or its “covert access section.”
— Raphael Satter (@raphae.li) September 23, 2026 at 9:44 PM
General tech and privacy
Canonical switches to two-week Ubuntu release cycle: Canonical is switching the Ubuntu Linux operating system from a four-week to a two-week release cycle. The company says the fast releases will allow it to patch security flaws faster. Canonical says the use of AI security tools has led to an explosion in the number of reported and patched vulnerabilities. [Canonical]

Chrome 154: Google has released version 154 of its Chrome browser. See here for security patches and webdev-related changes. The biggest changes in this release are the new system to allow websites to prompt users to install a desktop app and the removal of Privacy Sandbox APIs, Google's failed ad privacy system.
Microsoft files patent for in-game ad system: Microsoft has filed a patent application for an in-game advertising system where gameplay is interrupted after boss fights, cutscenes, quests, and multiplayer rounds to be shown ads and granted access to game features or more playtime. [Dexerto]
YouTube gets custom feeds: Google has added a new YouTube feature named Custom Feeds that lets users enter a few keywords and create a custom feed for their YouTube home page. [YouTube]

Government, politics, and policy
OpenAI gives Ukraine access to Daybreak: OpenAI has granted Ukraine access to its Daybreak AI cyber defence program to help the country protect its critical infrastructure from cyberattacks. The program allows cyber defenders to use advanced AI models to automate cyber-defense work. The move comes just as Russian hacking groups are increasingly adopting AI for attacks on Ukrainian organizations. France, Germany, Poland, and the EU's cybersecurity agency also have Daybreak access. [OpenAI]
US needs more cyber: A Pentagon official says the US government's needs for cyber capabilities far exceed the current options and supply. Pentagon assistant secretary of defense for cyber policy Katie Sutton says the role of cyber operations has shifted from disruptions to "an integrated tool of cyber warfare." Current US leaders are more inclined to use cyber because they view it as a tool "below the level of armed conflict." [CyberScoop]
US CVE program: CISA has published a document on the CVE programs' future and how it wants partners to help with identifying and triaging bugs. [CISA]
US Telecommunications Cybersecurity and Resilience Act: US lawmakers have introduced a bill to create a voluntary framework to strengthen telecommunications cybersecurity. The framework would be developed by experts from the government and the private sector. It aims to improve the sector's readiness and defenses against Salt Typhoon-type of hacks. [Sen. Warner, PDF]
Cybersecurity and AI Board of Investigations Act: US lawmakers have introduced legislation to establish an independent board to investigate major cybersecurity incidents, including those caused and assisted by AI. The Cybersecurity and AI Board of Investigations will have subpoena authority, similar to the National Transportation Safety Board. The board will investigate hacks of US critical infrastructure and security incidents caused by AI agents, like the recent wave of OpenAI and Anthropic hacks. [Sen. Markey]
New Europol boss: The European Council has selected German police official Jürgen Ebner as Europol's new executive director, the agency's de-facto boss. He still needs approval from the European Parliament before the Council can issue a formal appointment. [Politico Europe]
European Cybersecurity Alert System not yet operational: The European Union spent €1.4 billion on an early cyberattacks warning system but after 20 months, the project is still not operational. [EU ECA // Euronews]
UK to establish anti-disinformation center: The UK will establish a new center to fight online disinformation carried out by foreign hostile states. The new center will detect, attribute, and disrupt disinformation campaigns targeting British audiences. British Prime Minister Andy Burnham says the center will also help other countries if needed. The UK joins France as the other major EU power to have an anti-disinformation body. [The Record]
Sponsor section
In this Risky Business sponsor interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin will explain how Entra Agent ID can introduce new identity relationships and potential attack paths.
Arrests, cybercrime, and threat intel
US arrests Oxygen Forensics CEO: The US has arrested the CEO of a digital forensics company for lying to the government about its real ownership. Oxygen Forensics CEO Lee Reiber was arrested in Idaho on Sunday. The Justice Department charged Reiber with lying to the government about his company's ownership when applying for government contracts. The DOJ says Oxygen Forensics was actually owned by five Russian nationals and its software was developed in Russia. The agency has now seized Oxygen domains and servers. One of the company's Russian owners, Oleg Sergeyevich Davydov, was also arrested in London. Oxygen's US government contracts included the Pentagon, Homeland Security Investigations, the US Secret Service, and more. [DOJ]
Curious, Oxygen Forensics's website is down and they dropped out of a lawsuit. Are they closing up shop?
— Jurre van Bergen (@DrWhax) September 23, 2026
Latvia arrests hacker: Latvian authorities have arrested a 23-year-old man for hacking two local companies. The suspect exploited bugs in public websites, stole sensitive data, and then tried to extort the companies for ransoms. One of the victims has been identified as device repair company TSC. [Latvian State Police]
Ryuk member gets two years in prison: A US judge has sentenced an Armenian man to two years in prison for participating in attacks with the Ryuk ransomware. Karen Serobovich Vardanyan was arrested and extradited from Ukraine last year. He was a member of the Ryuk gang between March 2019 and June 2020, where he used the hacker nickname of Maneeken. [The Record]
Coinbase phisher gets 12 years: A US judge has sentenced a Brooklyn man to 12 years in prison for stealing almost $16 million worth of cryptocurrency from Coinbase users. Ronald Spektor contacted users posing as Coinbase support and tricked them into moving their funds to one of his crypto wallets. He scammed around 100 Coinbase customers. Investigators linked his home IP addresses to wallets that received stolen funds. Spektor lost $6 million of the stolen funds to crypto gambling. [Brooklyn District Attorney's Office]
Rydox admin pleads guilty: A Kosovo national has pleaded guilty to running the Rydox cybercrime marketplace. Ardit Kutleshi created and ran Rydox, an illicit marketplace to buy and sell stolen personal information. The FBI seized Rydox and arrested Kutleshi in December 2024. He was extradited to the US the next year. [DOJ]
Meta bans scammer accounts and pages: Meta has banned more than 3.7 million accounts and pages that peddled scams on Facebook and Instagram. Most of the suspended content were "shell pages" that were inactive and being prepared for future scams. The Singapore police reported the fraudulent accounts. [Meta // Singapore Police Force]
Data-harvesting network: Qurium looks at a giant network of sweepstakes sites that are illicitly collecting user data. [Qurium]
"The investigation found that these apparently separate operations repeatedly converge on infrastructure and companies associated with Norwegian digital advertising company Advertis AS. Among the links identified by Qurium are shared technical infrastructure, common data-handling entities and privacy-policy systems, as well as historical domain-registration records showing that verticalmailer.com, one of the investigated sweepstakes brands, was registered by Cristian Ghica, CEO of Advertis."
Hacker uses AI to steal 600k credit cards: A threat actor is using open-source AI tools to hack online retailers at scale and deploy card-stealing skimmer scripts. According to Gambit Security, the hacker has breached at least 27 companies and stole more than 600,000 credit card records. The three AI tools in the attacks are Cairn, Hermes, and Strix. The attacker configured the tools and left them to run the attacks with minimal oversight. The tools were configured using Chinese language prompts, which could indicate the attacker's nationality. [Gambit Security]
Google goes after Mellowtel botnet: Google has removed a cluster of Chrome extensions from the Web Store that enrolled user browsers into a web-scraping botnet. The extensions contained versions of Mellowtel, an SDK for sharing a user's internet bandwidth. Security firm Spur says the number of Mellowtel proxy nodes fell from 90,000 to 18,000 after Google's action. Extensions that removed the SDK were allowed back on the Web Store. [Spur]
Storm-2570 profile: Microsoft's security team looks at Storm-2570, a ransomware affiliate linked to multiple ransomware payloads as it hopped between different RaaS platforms. This includes Qilin, DragonForce, Anubis, and BERT. [Microsoft]
UNK_CondorFiltration targets LATAM: A threat actor is targeting the M365 accounts of organizations across Latin America. The group, UNK_CondorFiltration, is using TeamFiltration, a tool to enumerate Entra ID accounts and launch password-spraying attacks. [Proofpoint]
HR and payroll campaign: A threat actor is contacting companies, posing as legitimate HR and payroll companies, and trying to get their employees to install malicious desktop apps. [Allure Security]
KongTuke spreads SystemBC: According to a new report, the KongTuke e-crime group is now spreading the SystemBC RAT via ClickFix lures. [Deception.Pro]
iOS exploit chain targets Italian users: Italian security firm D3Lab has found a phishing campaign redirecting iOS users running iOS 17.2.1 and below to a page running exploits against Safari. [D3Lab]
"The module names, three-stage organisation, loader structure and associated administration panel link the sample to Coruna Pro V2, a codebase circulated publicly as a research toolkit and subsequently expanded with a management backend. The service exposed on port 7080 explicitly uses the name Coruna-Pro-V2."
Malicious Firefox extension: Socket has spotted a malicious Firefox extension (PDF Identity Verifier) that fetches its payload after installation to evade detection, steals Google session cookies, and automates account takeovers. [Socket Security]
New supply chain attack: A threat actor has compromised libraries on npm and PyPI for yet another worm-based supply chain attack. This one uses a Go-based worm that researchers are calling Sckit. [Aikido Security // SafeDep // Semgrep // Step Security]
Placeholder third-party[.]com domain delivers malware: A threat actor has taken over the third-party[.]com domain to serve malware via ClickFix attacks. The domain is a popular placeholder URL used in the documentation of many tools and libraries. According to Manifold Security, users who landed on the site were asked to copy-paste malicious PowerShell commands that install malware on their systems. The malicious ClickFix prompt is still live, but the domain has now been added to most browser blocklists. [Manifold Security]

Malware technical reports
Exvicy: Sekoia researchers have discovered Exvicy, a new traffic distribution system that is being used to automate the creation of ClickFix pages and then redirect traffic to it from hacked sites. [Sekoia]
DarkMe RAT: Huntress researchers have documented two recent campaigns spreading DarkMe, a VB6 RAT historically linked to a bunch of e-crime activity. Ongoing campaigns compromise legitimate Ukrainian business sites and use Ukrainian language CAPTCHAs. [Huntress]
BotHelper RAT: Point Wild researchers have found a previously undocumented Windows RAT named BotHelper. [Point Wild]
Psychedelic Stealer: Arctic Wolf has discovered a fake Cloudflare CAPTCHA campaign delivering Psychedelic Stealer, a new infostealer that targets browser passwords, account tokens, and wallet data. [Arctic Wolf]
MacSync infostealer: Kaspersky has published a technical report on MacSync, a pretty popular macOS infostealer that entered the malware market last year. The malware apparently received a major code overhaul this month. [Kaspersky]
CARBONATO botnet: A threat actor has used an AI agent to build a botnet from hacked Docker servers. The attacker used the Hermes AI to automate scans for exposed Docker systems, compromise servers, and spread to internal networks. Security firm ThreatDown discovered the operation after the threat actor exposed their own files via one of the Docker servers. Clues suggest the botnet's operator is based in Costa Rica. [ThreatDown]
PavokwiLoader: The Malbear Labs team has discovered a new malware loader named PavokwiLoader. The loader is already being used in the wild. [Malbear Labs]
Sauron Loader: And speaking of new loaders, there's another one named Sauron that's being advertised on underground hacking forums. According to DCSO, the malware is sold exclusively to Russian-speaking individuals and has already been seen in the wild in Germany. [DCSO]
RemControl Android banking trojan: A new Android banking trojan named RemControl is targeting banking customers in Canada, the Middle East, and Western Europe. According to security firm Group-IB, parts of the trojan's infrastructure were coded using AI tools. RemControl developers tricked the AI coding assistant that it was creating a parental monitoring application but used the code for the trojan's phishing overlays and backend servers. [Group-IB]
RedWing Android banking trojan: Russian security firm F6 has published another report on RedWing, the Android banking trojan that launched this year and can target Russian banks. [F6]
Corp MDM Android spyware: Researchers have spotted a new Android spyware strain named Corp MDM. The malware has been used in campaigns targeting logistics firms. It appears to have been coded with AI and can exfiltrate newly received SMS content, divert calls, and maintain a hidden foreground service. [Have I Been Squatted]
Sponsor section
In this sponsored Soap Box edition of the show, Patrick Gray and James Wilson talk about red teaming AI systems with Russel Van Tuyl, Vice President of Services at elite penetration testing firm SpecterOps. SpecterOps is the company behind attack path enumeration tool Bloodhound and Bloodhound Enterprise, but they're also a pentest and red teaming shop with world class expertise in popping shells on all sorts of interesting systems in all sorts of interesting places.
APTs, cyber-espionage, and info-ops
Max analysis: Researchers at InterSecLab have published an in-depth analysis of Max, Russia's state-mandated messaging applications, and all the ways the app can spy on its users and what data it collects. [InterSecLab]

Vulnerabilities, security research, and bug bounty
Security updates: Chrome, cPanel, Forcepoint, GitHub Enterprise, HP, HPE, MikroTik, Next.js, NVIDIA, OpenCode, Outlook, SolarWinds, TDengine, Ubiquiti, WordPress.
WordPress bug exploited within hours: Threat actors started exploiting a WordPress vulnerability hours after a patch was released on Tuesday. The vulnerability is an unauthenticated path traversal that can lead to remote code execution. All WordPress versions released over the past decade are vulnerable. [WordPress // Previdian // Wordfence // WordPress CVE-2026-87902 on GitHub]
And so it begins.
— Ryan Dewhurst (@ethicalhack3r) September 23, 2026
Started to see attempted WordPress RCE (CVE-2026-87902) exploitation in @PrevidianCyber honeypots from 104.194.9[.]227
They try to include /usr/local/lib/php/pearcmd.php
They try to write a file in /tmp/
Then try to include a Github hosted upload PHP file pic.twitter.com/wjerg34fXr
Roundcube bug exploited in the wild: Canada's cyber security agency says a Roundcube bug patched in May is now being exploited in the wild. This is CVE-2026-48842. [CCCS]
TDengine vulnerability: Ridge Security has published a write-up on a pre-auth DoS vulnerability that can crash TDengine databases with one packet. The database is widely used for industrial telemetry, energy, utilities, connected vehicles, and IoT environments. [Ridge Security // TDengine CVE-2026-42542]
TrustSink technique: Varonis researchers have developed TrustSink, a new technique that allows attackers to register a rogue external MFA provider for an account and use it as a persistent backdoor. [Varonis]
Cloudflare sandbox escape: Cloudflare has patched a vulnerability that could have allowed attackers to escape their sandbox and access cross-tenant data from its Containers feature. [Accomplish // Cloudflare]
Google PageBreak: Google says it developed a special AI agent named PageBreak that it has used to find vulnerabilities in its internal systems. [Google // Google Bug Hunters]
Infosec industry
Threat/trend reports: Datadome, F5, Gallup, Honeywell, NCC Group, Ox Security, Rockwell Automation, Travelers, and VikingCloud have recently published reports and summaries covering various emerging threats and industry trends.

New tool—Anthropic CVE Tracker: VulnCheck security researcher Patrick Garrity has released Anthropic CVE Tracker, a tool to discover vulnerabilities that credit the Anthropic research team and Project Glasswing.
BSides Tampa 2026 videos: Talks from the BSides Tampa 2026 security conference, which took place in May, are available on YouTube.
BruCON 2026: Talks from the BruCON 2026 security conference, which is taking place this week, are available on YouTube.
fwd:cloudsec Europe 2026 videos: Talks from the fwd:cloudsec Europe 2026 security conference, which took place this month, are now available on YouTube.
Risky Business podcasts
In this edition of Seriously Risky Business, Tom Uren and Patrick Gray talk about US Treasury Secretary Scott Bessent ruling out liability exemptions for AI companies. It's a good move.